2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28034 | MEDIUM | 6.1 | 1.7% | Nov 2, 2020 | WordPress before 5.5.2 allows XSS associated with global variables. |
| CVE-2020-28033 | HIGH | 7.5 | 2.6% | Nov 2, 2020 | WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam ... |
| CVE-2020-28032 | CRITICAL | 9.8 | 16.1% | Nov 2, 2020 | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. |
| CVE-2020-28031 | MEDIUM | 4.3 | 0.6% | Nov 2, 2020 | eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenti... |
| CVE-2020-28030 | HIGH | 7.5 | 2.0% | Nov 2, 2020 | In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by co... |
| CVE-2020-28002 | MEDIUM | 5.3 | 1.1% | Nov 2, 2020 | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty val... |
| CVE-2020-27992 | HIGH | 7.8 | 0.4% | Nov 2, 2020 | Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Won... |
| CVE-2020-27982 | MEDIUM | 6.1 | 5.3% | Nov 2, 2020 | IceWarp 11.4.5.0 allows XSS via the language parameter. |
| CVE-2020-27708 | HIGH | 7.8 | 0.6% | Nov 2, 2020 | A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either... |
| CVE-2020-27359 | MEDIUM | 5.4 | 0.8% | Nov 2, 2020 | A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScrip... |
| CVE-2020-27358 | MEDIUM | 4.3 | 2.0% | Nov 2, 2020 | An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export... |
| CVE-2020-25689 | MEDIUM | 6.5 | 1.5% | Nov 2, 2020 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in ... |
| CVE-2020-24881 | CRITICAL | 9.8 | 73.3% | Nov 2, 2020 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
| CVE-2020-23639 | CRITICAL | 9.8 | 3.1% | Nov 2, 2020 | A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a r... |
| CVE-2020-15914 | MEDIUM | 5.4 | 0.6% | Nov 2, 2020 | A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allo... |
| CVE-2020-14750 | CRITICAL | 9.8 | 99.3% | Nov 2, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions... |
| CVE-2020-14425 | HIGH | 7.8 | 39.4% | Nov 2, 2020 | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe... |
| CVE-2020-10937 | HIGH | 7.5 | 1.1% | Nov 2, 2020 | An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverag... |
| CVE-2020-3704 | HIGH | 7.5 | 0.5% | Nov 2, 2020 | u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device ma... |
| CVE-2020-3703 | CRITICAL | 9.8 | 0.7% | Nov 2, 2020 | u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r... |
| CVE-2020-3696 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Use after free while installing new security rule in ipcrtr as old one is deleted and this rule could still be in use ... |
| CVE-2020-3694 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapd... |
| CVE-2020-3693 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snap... |
| CVE-2020-3692 | CRITICAL | 9.8 | 0.9% | Nov 2, 2020 | u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input valid... |
| CVE-2020-3690 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Due to an incorrect SMMU configuration, the modem crypto engine can potentially compromise the hypervisor' in Snapdrag... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now